DEV Community

threataft
threataft

Posted on Originally published at threataft.com

Ghost CMS Mass Disclosure — 6 CVEs Including CVSS 8.1 Staff Session Bypass

A Ghost staff user with valid credentials can log into any other staff account using only the target's password — bypassing 2FA entirely.

CVE-2026-103283 (CVSS 8.1) leads a cluster of six vulnerabilities in Ghost CMS disclosed October 1. Here's the full picture:

CVE-2026-103283 (8.1) — Staff session bypass. Any authenticated staff user can impersonate any other staff member with just their password. 2FA does not protect against this. Fixed in 6.57.1.

CVE-2026-103271 (7.5) — Unauthenticated gated content access via the Content API. Subscription paywalls bypassed entirely. Fixed in 6.63.0.

CVE-2026-103266 (7.1) — Stripe Checkout abuse: unauthenticated attackers can attach subscriptions to member accounts and inject XSS into newsletters. Fixed in 6.62.0.

CVE-2026-103279 (6.8) — Session cookies stay valid after a password change. Standard breach response doesn't work. Fixed in 6.34.0.

CVE-2026-103291 (6.3) — SSRF via image dimension refetching. Staff users can hit cloud metadata endpoints. Fixed in 6.51.0.

CVE-2026-103275 (2.2) — Password hash inference via Admin API bulk endpoints. Fixed in 6.58.0.

Action: Upgrade to Ghost 6.63.0, rotate staff credentials, invalidate all active sessions.

Full breakdown → https://threataft.com/articles/ghost-cluster-cve-2026-103283-103271-103266-103279-103291-103275

Top comments (0)